CWE-130 长度参数不一致性处理不恰当 类弱点 71 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-130属于长度参数不一致漏洞,指程序解析数据时未正确处理长度字段与实际数据长度不匹配的情况。攻击者通过篡改输入的长度参数,使其与实际数据不符,诱导应用程序执行意外行为,如缓冲区溢出或逻辑错误。开发者应严格验证长度字段与数据实际长度的一致性,并在解析前进行边界检查,确保数据完整性,从而防止此类漏洞被利用。
int processMessageFromSocket(int socket) { int success; char buffer[BUFFER_SIZE]; char message[MESSAGE_SIZE]; // get message from socket and store into buffer //Ignoring possibliity that buffer > BUFFER_SIZE if (getMessage(socket, buffer, BUFFER_SIZE) > 0) { // place contents of the buffer into message structure ExMessage *msg = recastBuffer(buffer); // copy message body into string for processing int index; for (index = 0; index < msg->msgLength; index++) { message[index] = msg->msgBody[index]; } message[index] = '\0'; // process message success = processMessage(message); } return success; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-5766 | ASGI请求通过文件上传限制绕过潜在的服务拒绝漏洞 — Django | 5.3 | Medium | 2026-05-05 |
| CVE-2026-33846 | GnuTLS DTLS握手分片重组堆溢出致服务拒绝漏洞 — Red Hat Hardened Images | 7.5 | High | 2026-05-04 |
| CVE-2026-3868 | Moxa EDR-8010 Series和Moxa EDR-G9010 Series 安全漏洞 — EDR-8010 Series | 7.5AI | HighAI | 2026-04-27 |
| CVE-2026-5265 | OVN 安全漏洞 — Fast Datapath for Red Hat Enterprise Linux 8 | 6.5 | Medium | 2026-04-24 |
| CVE-2026-5367 | OVN 安全漏洞 — Fast Datapath for Red Hat Enterprise Linux 8 | 8.6 | High | 2026-04-24 |
| CVE-2026-41035 | Rsync 安全漏洞 — rsync | 7.4 | High | 2026-04-16 |
| CVE-2026-33555 | HAProxy 安全漏洞 — HAProxy | 4.0 | Medium | 2026-04-13 |
| CVE-2026-40199 | Net-CIDR-Lite 安全漏洞 — Net::CIDR::Lite | 7.5 | - | 2026-04-10 |
| CVE-2026-34831 | Rack 安全漏洞 — rack | 4.8 | Medium | 2026-04-02 |
| CVE-2026-25572 | Siemens SICAM SIAPP SDK 安全漏洞 — SICAM SIAPP SDK | 5.1 | Medium | 2026-03-10 |
| CVE-2026-25571 | Siemens SICAM SIAPP SDK 安全漏洞 — SICAM SIAPP SDK | 5.1 | Medium | 2026-03-10 |
| CVE-2025-48022 | Yokogawa Electric Vnet/IP Interface 安全漏洞 — Vnet/IP Interface Package | 7.5AI | HighAI | 2026-02-13 |
| CVE-2025-14847 | MongoDB Server 安全漏洞 — MongoDB Server | 7.5 | High | 2025-12-19 |
| CVE-2025-8531 | Mitsubishi Electric MELSEC-Q Series 安全漏洞 — MELSEC-Q Series Q03UDVCPU | 6.8 | Medium | 2025-09-19 |
| CVE-2025-10458 | Zephyr 安全漏洞 — Zephyr | 7.6 | High | 2025-09-19 |
| CVE-2025-5514 | Mitsubishi Electric MELSEC iQ-F Series CPU 安全漏洞 — MELSEC iQ-F Series FX5U-32MT/ES | 5.3 | Medium | 2025-08-25 |
| CVE-2025-54646 | Huawei HarmonyOS和Huawei EMUI 安全漏洞 — HarmonyOS | 5.1 | Medium | 2025-08-06 |
| CVE-2023-53157 | Rosenpass 安全漏洞 — rosenpass | 5.3 | Medium | 2025-07-27 |
| CVE-2025-52949 | Juniper Networks Junos OS和Juniper Networks Junos OS Evolved 安全漏洞 — Junos OS | 6.5 | Medium | 2025-07-11 |
| CVE-2025-53604 | web-push crate 安全漏洞 — web-push | 4.0 | Medium | 2025-07-05 |
| CVE-2025-23247 | NVIDIA CUDA toolkit 安全漏洞 — NVIDIA CUDA Toolkit | 4.4 | Medium | 2025-05-27 |
| CVE-2025-29784 | NamelessMC 安全漏洞 — Nameless | 7.5 | High | 2025-04-18 |
| CVE-2025-29931 | Siemens TeleControl Server Basic 安全漏洞 — TeleControl Server Basic | 3.7 | Low | 2025-04-17 |
| CVE-2025-30659 | Juniper Networks Junos OS SRX 安全漏洞 — Junos OS | 7.5 | High | 2025-04-09 |
| CVE-2025-32366 | ConnMan 安全漏洞 — ConnMan | 4.8 | Medium | 2025-04-05 |
| CVE-2024-53856 | rPGP 安全漏洞 — rpgp | 7.5 | High | 2024-12-05 |
| CVE-2024-47293 | Huawei HarmonyOS 安全漏洞 — HarmonyOS | 4.7 | Medium | 2024-09-27 |
| CVE-2024-20416 | Cisco RV340 和 Cisco RV345 安全漏洞 — Cisco Small Business RV Series Router Firmware | 6.5 | Medium | 2024-07-17 |
| CVE-2024-38010 | Microsoft Windows Secure Boot 安全漏洞 — Windows 10 Version 1809 | 8.0 | High | 2024-07-09 |
| CVE-2024-38011 | Microsoft Windows Secure Boot 安全漏洞 — Windows 10 Version 1809 | 8.0 | High | 2024-07-09 |
CWE-130(长度参数不一致性处理不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 71 条 CVE 漏洞。